Recent Articles

Evolving Business And IT Rules To Match New Demand
Michael Cote of Redmonk had a nice piece on over on his People over Process blog. He made a series of great points about the risk of business and IT people not being aligned - risks to the business and to IT.

Google To Enter The OS Market For Netbooks
Google certainly doesn't rest on its laurels, that's for sure. They are, first and foremost a search engine, but the success of their search business has fathered so many products that aren't search related at...

Building And Developing Railo For Testing
As of today, you can easily build your very own version of Railo from the latest source code in Subversion! This blog post will take you through all the steps necessary...

The Truth About Technical Accessibility
This has been stewing for a while. Just brimming under the surface. An brewing anger towards companies that do not understand accessibility, nor the commitment that is required to be accessible, but will give it a light...

Q&A Site For System Administrators Gaining Momentum
System administrators now have a new resource to turn to whenever they run into a problem. A site called Server Fault has been launched in public beta, and it's...

Windows 7: Fast Enough For You?
The recent release candidate of Windows 7 is still the buzz. If you're like me, one thing that you're very concerned about in a new operating system is speed. Is the thing going to be fast enough?


08.07.09

Understanding A Denial Of Service Attack

By Dave Taylor

I heard on the news today that my favorite social network, Twitter, is being plagued by what they called a "denial of service attack". What on Earth is that? They're forced to not actually get service and it's an attack? I mean, I've been to restaurants where I experience a denial of service, but how can something like that affect Twitter or Facebook or whatever?

Dave's Answer:

Ha! I love the joke about denial of service at a restaurant. You could even have said that was what launched the entire Civil Rights movement decades ago, but that wouldn't have been focused on what's going on right now with Twitter and Facebook, among other sites.

The idea behind an actual denial of service attack (often called a DoS) is that if you flood the Web servers of a popular site with spurious, bogus queries, it'll be so busy answering those bogus requests that it'll have to reject legitimate connect requests from real users.

Think of it this way: if you were answering phones for a company and suddenly found that seemingly every single call was a prank, wouldn't the people who were trying to call the company for legitimate reasons just get a busy signal, while you, the operator, were stuck dealing with and hanging up on the bogus callers?

There are also a lot of ways to implement a DoS too, as it happens, but the most common are so-called "smurf attacks" (technically, ICMP floods), where incorrectly configured network devices allow queries to be sent to all machines on a network, rather than a specific one. The more complex the network, the more this kind of thing can be crippling to the service.

Get a Holistic View of Your Complete IT Infrastructure - Free Trial

Other ICMP floods include "ping floods", where ping packets are sent incessantly, or SYN floods, where, you guessed it, SYN packets are sent with forged sender addresses.

Other types of Denial of Service attacks include "teardrop attacks", "peer to peer attacks", "application level floods", "nukes" and "distributed attacks" (also known as DDoS, or distributed denial of service). The lattermost is particularly tough because hundreds or even thousands of machines can all be unknowingly contributing to the attack (if you really want to get into the weird nomenclature, it's usually trojan attacks that compromise the individual machines, making them zombie agents.

Suffice to say, what's happening to Twitter is very hard to address because if the tsunami of bogus queries are indistinguishable from legitimate ones, how can they shut it down or block it?

To learn more about Denial of Service attacks, check out the informative article on Wikipedia.

Comments


About the Author:
Dave Taylor is known as an expert on both business and technology issues. Holder of an MSEd and MBA, author of twenty books and founder of four startups, he also runs a marketing company and consults with firms seeking the best approach to working with weblogs and social networks. Dave is an award-winning speaker and frequent guest on radio and podcast programs.

AskDaveTaylor.com
http://www.intuitive.com/blog/
About SysAdminNews
SysAdminNews is a collection of articles, news and commentary designed to keep system administrators informed about the latest trends impacting their profession. Updates and Advice for System Administrators





SysAdminNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
SysAdminNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITManagementNews.com





-- SysAdminNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2009 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


Database Forum Updates and Advice for System Administrators SysAdminNews News Archives About Us Feedback SysAdminNews.com About Article Archive News Downloads WebProWorld Forums iEntry Advertise Contact Jayde